With a specially crafted Python script, an attacker could send
continuous startMeasurement commands over an unencrypted Bluetooth
connection to the affected device. This would prevent the device from
connecting to a clinician's app to take patient readings and ostensibly
flood it with requests, resulting in a denial-of-service condition.
Metrics
Affected Vendors & Products
References
History
Fri, 14 Feb 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 13 Feb 2025 22:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | With a specially crafted Python script, an attacker could send continuous startMeasurement commands over an unencrypted Bluetooth connection to the affected device. This would prevent the device from connecting to a clinician's app to take patient readings and ostensibly flood it with requests, resulting in a denial-of-service condition. | |
Title | Qardio Heart Health IOS and Android Application and QardioARM A100 Uncaught Exception | |
Weaknesses | CWE-248 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2025-02-14T18:11:19.931Z
Reserved: 2025-02-10T15:16:25.257Z
Link: CVE-2025-24836

Updated: 2025-02-14T18:11:13.515Z

Status : Received
Published: 2025-02-13T22:15:12.270
Modified: 2025-02-13T22:15:12.270
Link: CVE-2025-24836

No data.